Technical · Validation & data

Data integrity

Data integrity is the extent to which data is complete, consistent and accurate throughout its lifecycle — attributable to who generated it, contemporaneous with the activity, and preserved in a form that can be reconstructed later.

In one line

Data integrity is the extent to which data is complete, consistent and accurate throughout its lifecycle — attributable to who generated it, contemporaneous with the activity, and preserved in a form that can be reconstructed later.

Plain-English explanation, then the primary regulation it comes from.

Explanation

Understanding data integrity

Data integrity is not a separate compliance topic bolted onto GMP; it is the property that makes every other record meaningful. A validation report, a batch record and a release decision are only worth what the underlying data is worth. That is why data integrity findings escalate quickly — they undermine the evidential basis of everything else on the site.

The distinction between static and dynamic records matters for what you must retain. A static record is a fixed image, such as a paper record or a PDF. A dynamic record allows interaction — a chromatogram that can be reprocessed with different integration parameters is dynamic, and printing it produces a static picture that loses the ability to reconstruct what was done. Retaining only the printout for a dynamic record is a well-established finding.

Most real-world gaps are unglamorous. Audit trails enabled but never reviewed. Shared logins that make records unattributable. Uncontrolled spreadsheets. Hybrid paper-and-electronic systems where neither record is definitive. Original observations recorded on a scrap of paper and transcribed later, which breaks contemporaneity and originality at once.

The governance point is the one that changes outcomes. Data integrity is largely a design and culture problem: systems that make the compliant route the easy route, and an environment where reporting a problem is safe. Where people are penalised for raising deviations, pressure to make data look acceptable is created by management, not by individuals — and inspectors are alert to that pattern.

What it requiresThe substance of the requirement, stated plainly.
ALCOA+ as the yardstick
Attributable, Legible, Contemporaneous, Original, Accurate, plus Complete, Consistent, Enduring and Available.
Static vs dynamic records
Dynamic records must be retained in a form that preserves interaction and reprocessing history.
Audit trail review
A defined responsibility, performed at a defined frequency, with the review itself recorded.
Attributability
Individual accounts and signatures; shared credentials break the chain entirely.
Data lifecycle
Generation, processing, review, reporting, retention, retrieval and disposal — all in scope.
Culture and design
Systems that make compliance the path of least resistance, and a climate where problems can be raised.
Where it goes wrongThe part a definition alone will not tell you.

Common failure modes

  • Retaining only printouts of dynamic records such as chromatograms.
  • Shared logins, or analysts working under a supervisor's account.
  • Recording results on scrap paper and transcribing them into the record later.
  • Audit trail review assigned to nobody, or assigned to the person whose work it would scrutinise.
Primary sourcesAlways verify against the primary source before acting; guidance is revised.

Where this is written down

One GMP problem. Multiple perspectives.

Data integrity seen from four accountabilities

Data integrity is the property that makes every other record meaningful — which is why its failures escalate faster than almost anything else on a site.

Quality

ALCOA+ as a diagnostic, not a slogan

Can we reconstruct what actually happened?

Most real gaps are unglamorous: audit trails enabled but never reviewed, shared logins that destroy attributability, uncontrolled spreadsheets performing GMP calculations, and hybrid paper-electronic systems where nobody has defined which record is the raw data.

Assign audit trail review to a named role with a defined frequency, and inventory the spreadsheets and instrument software that are systems but are not on the system list.

GMP for Quality
CEO

It undermines the evidence for everything else

Why do these findings escalate so quickly?

A validation report, a batch record and a release decision are only worth what the underlying data is worth. A data integrity finding therefore calls into question the evidential basis of the whole site, not just the record in front of the inspector.

Treat data integrity as a culture and design question at your level: where people are penalised for raising problems, pressure to make data look acceptable is created by management, not by individuals.

GMP for CEO
CFO

Scope expands beyond the finding

What is the exposure if this is found?

Because the finding questions the reliability of records generally, remediation rarely stays contained to the system where it was found. Retrospective review, system remediation and re-validation across an estate is a materially larger programme than fixing one audit trail.

Fund the inventory and audit trail review programme before a finding sets the scope. Pre-emptive scope is chosen; post-finding scope is negotiated.

GMP for CFO
COO

Access control and review are operational changes

What does remediation do to the site?

Removing shared logins, enforcing individual accounts and instituting audit trail review change how people work at the line and in the laboratory. Done badly this creates workarounds; done well it is largely invisible after a few weeks.

Design the controls so the compliant route is the easy route. Controls that fight the workflow are the ones that quietly stop being followed.

GMP for COO
Related

Read next

Applying this to your site

Knowing the requirement is not the same as closing the gap

If you want to know where your site actually stands against this, the readiness score covers seven quality-system domains in twenty questions, and takes about ten minutes.